# Rockwell RSLinx buffer overflow enables remote code execution

Published: 2026-06-16 · Severity: high · Sectors: manufacturing, energy, infrastructure
Canonical: https://vorant.io/reports/921c5c91-e9a9-51c8-bba7-8a143da33dbb/rockwell-rslinx-buffer-overflow-enables-remote-code-execution

> A stack-based buffer overflow in Rockwell Automation RSLinx Classic versions 4.50.00 and earlier allows remote code execution and denial of service against industrial control systems.

CISA has published an advisory for CVE-2020-13573, a stack-based buffer overflow vulnerability in Rockwell Automation's RSLinx Classic software. The flaw affects all versions up to and including 4.50.00 and can be exploited remotely to execute arbitrary code or cause denial of service conditions where the application becomes unresponsive and fails to recover automatically.

The vulnerability impacts critical infrastructure sectors including critical manufacturing, energy, food and agriculture, and water/wastewater systems worldwide. Rockwell Automation has released version 4.60.00 to address the issue and provides patch BF31213 for organizations unable to upgrade immediately.

No active exploitation has been reported to CISA at the time of publication. The vendor recommends implementing network segmentation, minimizing internet exposure of control systems, and using secure remote access methods as additional defensive measures.

## Mentioned in this report

- Vulnerabilities: CVE-2020-13573

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-02

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/921c5c91-e9a9-51c8-bba7-8a143da33dbb/rockwell-rslinx-buffer-overflow-enables-remote-code-execution.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
